Privacy Policy
Version 2026-07-30. All policies
DRAFT FOR ATTORNEY REVIEW. This document has not been reviewed by a qualified legal practitioner and must not be published in this form. Square-bracket placeholders must be completed before publication. See docs/legal-review-notes.md for the open questions.
Service: Ideas Central, a browser-based parametric part generator at https://www.ideas-central.com
Last updated: [DATE OF PUBLICATION]
Version: [VERSION]
1. In short
Ideas Central generates 3D-printable mechanical parts in your browser. The geometry is built on your own device. We hold your account details, the parameter sets you choose to save, files you choose to upload or export, a record of your exports for quota and billing purposes, and your subscription status.
We do not receive your card details. We do not sell personal information. We do not run advertising, profiling or automated decision-making that has legal effects on you. We do not train any model on your uploads unless you separately opt in.
This single policy is written to satisfy the Protection of Personal Information Act 4 of 2013 (South Africa, our primary regime), the EU General Data Protection Regulation, the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA. Where a regime gives you something extra, it is called out in the relevant section.
2. Who is responsible for your information
| Field | Value |
|---|---|
| Trading name | Ideas Central |
| Legal entity | [COMPANY LEGAL NAME] (Pty) Ltd |
| Company registration number | [CIPC REGISTRATION NUMBER] |
| VAT number | [VAT NUMBER OR "not VAT registered"] |
| Registered address | [STREET ADDRESS], South Africa |
| Country of establishment | South Africa |
| General contact | info@ideas-central.com |
| Legal notices | legal@ideas-central.com |
| Privacy contact | privacy@ideas-central.com |
Under POPIA we are the responsible party. Under the GDPR and UK GDPR we are the controller. Under the CCPA we are a business.
Information Officer
| Field | Value |
|---|---|
| Information Officer (POPIA) | [NAME] |
| Contact | privacy@ideas-central.com |
POPIA makes the head of a private body the Information Officer by default, and section 55 read with the Regulator's registration guidance requires that the Information Officer be registered with the Information Regulator of South Africa before performing their duties. Action item: this registration must be completed before publication. It is listed in docs/legal-review-notes.md.
We have not appointed an EU or UK representative under GDPR Article 27 / UK GDPR Article 27. Whether one is required is an open question for our attorney and is flagged in the review notes.
3. What we collect, why, and how long we keep it
The table below is the complete list. Retention periods come from our internal data register and are binding on us.
| Data | Why we hold it | GDPR / UK GDPR lawful basis | POPIA justification (s 11) | Where it lives | How long we keep it |
|---|---|---|---|---|---|
| Account data — email address, name, country | To create and operate your account, authenticate you, and contact you about the service | Art 6(1)(b) performance of a contract | s 11(1)(b) necessary to conclude or perform a contract with you | Supabase profiles |
Life of the account, then 30 days |
| Credentials — password hash or OAuth identifier | To sign you in securely. We never see or store a plain-text password | Art 6(1)(b) performance of a contract | s 11(1)(b) | Supabase Auth | Life of the account, then 30 days |
| Saved part specifications — the parameters of a part, not the geometry | So you can reopen, edit and re-generate a part you saved | Art 6(1)(b) performance of a contract | s 11(1)(b) | Supabase parts |
Life of the account |
| Uploaded and exported files | To store models you upload for editing and files you choose to keep | Art 6(1)(b) performance of a contract | s 11(1)(b) | Supabase Storage, private bucket | Life of the account |
| Usage events — what was exported and when | To enforce your plan's export quota, to detect abuse, and to resolve billing disputes | Art 6(1)(b) performance of a contract, and Art 6(1)(f) legitimate interests in quota enforcement and abuse prevention | s 11(1)(b) and s 11(1)(f) legitimate interests of the responsible party | Supabase usage_events |
24 months |
| Search queries — the text typed into the part search and describe boxes, and what it matched | To find the parts customers want that the catalogue lacks, so they can be built | Art 6(1)(f) legitimate interest in improving the catalogue | s 11(1)(f) legitimate interests of the responsible party | Supabase search_queries |
12 months |
| Subscription records — plan, status, billing period | To give you the entitlements you paid for and to keep accounting records | Art 6(1)(b) performance of a contract, and Art 6(1)(c) legal obligation for the retention period | s 11(1)(b) and s 11(1)(c) compliance with an obligation imposed by law | Supabase subscriptions |
7 years, as a tax record |
| Payment card details | We never receive them. Paddle takes payment as merchant of record and does not pass card data to us. We see only the plan, status and period | Not applicable to us | Not applicable to us | Never in our systems | n/a |
| IP address hash — for the anonymous export quota | To allow one free export per 24 hours without an account, and to prevent that allowance being abused. We store a hash, not the address | Art 6(1)(f) legitimate interests in preventing abuse of a free allowance | s 11(1)(f) legitimate interests of the responsible party | Supabase anon_quota |
48 hours |
| Transactional email — verification, password reset, receipt and service notices, and the delivery metadata that goes with them | To confirm your address, let you recover your account, and send notices you need | Art 6(1)(b) performance of a contract | s 11(1)(b) | Resend and Supabase Auth | [CONFIRM RETENTION WITH PROVIDER — see review notes] |
| Server and edge logs — request metadata, IP address, user agent, timestamps, error traces | To keep the service available, investigate faults, and defend against attack and fraud | Art 6(1)(f) legitimate interests in security and availability | s 11(1)(f) legitimate interests of the responsible party | Cloudflare edge and Supabase platform logs | [CONFIRM PROVIDER LOG RETENTION — see review notes] |
Where we rely on legitimate interests, we have weighed our interest against your rights. In each case the processing is limited to what quota enforcement, security or fault diagnosis actually needs, and none of it is used to build a profile of you. You can object to legitimate-interest processing: see section 7.
Where you give consent (for example, opting in to marketing email or to a future model-training programme), you can withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.
Special categories and children's data
We do not ask for and do not want special personal information under POPIA section 26 or special category data under GDPR Article 9. Do not put health, biometric, political, religious, trade union, sex life, or criminal record information into part names, file names or support messages.
4. What Ideas Central does not do
This section is a commitment, not a description of current practice that might quietly change.
Geometry is generated in your browser. When you describe or configure a part, the parameter set is evaluated and the mesh is built on your own device. The design you are working on does not reach our servers at all unless one of these four things happens:
- You save the part to your account, in which case the parameter set (not the geometry) is stored in
parts. - You search for or describe a part. The text you type into the search and describe boxes is kept for 12 months, together with which template it matched (if any). We use it for one thing: finding the parts people want that the catalogue does not have yet, so we can build them. It is stored against a random per-browser identifier, not your IP address; if you are signed in it is linked to your account so duplicate asks are not double-counted. Do not put personal information in a part search — and if you do, you can ask us to delete it at privacy@ideas-central.com.
- You download a file. Every export format, including STEP, is written in your browser. What reaches us is the record of the download itself: the template, the format, the parameter set and the validation warnings that were showing at the time. We keep that to run your quota, to settle a billing dispute, and so that a part which later fails can be traced to the exact inputs that produced it.
- You upload a model or an image deliberately. An uploaded image is processed entirely in your browser — the traced model, not the photograph, is what exists; the image itself is never transmitted to us.
If you do none of those things, we have no record of what you designed.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in the CCPA/CPRA. We have never done so.
We run no advertising on the service and set no advertising, retargeting or cross-site tracking cookies. See the Cookie Policy.
We do not carry out profiling or automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of GDPR Article 22 and POPIA section 71. Quota counting is arithmetic against a published limit, not a decision about you.
We do not train any model on your uploads, your saved parts, or your generated geometry without your separate, specific, opt-in consent. Geometry on Ideas Central is produced by deterministic template code, not by a generative mesh model, so there is no model to train in the first place. If that ever changes, participation would be opt-in, revocable, and announced in advance. Silence would not be treated as consent, and using the service would not be treated as consent.
5. Who else processes your information
We use a small number of operators (POPIA) / processors (GDPR) / service providers (CCPA). Each is bound by a written contract to process personal information only on our instructions and to keep it secure.
| Processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | AWS, region set at project creation — [CONFIRM: eu-central-1 or af-south-1] |
| Paddle.com Market Ltd | Payments, merchant of record, invoicing, tax | United Kingdom / EU |
| Cloudflare, Inc. | Static hosting, CDN, DNS, DDoS protection | Global edge |
| Resend / Supabase Auth | Transactional email (verification, reset, receipts) | EU/US |
| Plausible Analytics | Cookieless, aggregate site analytics — optional | EU (Germany) |
Paddle is the merchant of record. Paddle sells the subscription to you and is the seller of record on your invoice; Ideas Central supplies the service. Paddle collects and holds your payment details as a controller in its own right for that transaction, under its own privacy notice. This is why we can say honestly that we never touch your card data.
Plausible is cookieless and produces aggregate site statistics only. It sets no cookie, assigns no persistent identifier, and does not follow you across sites. It is optional and may not be enabled at all.
We will also disclose personal information where we are legally obliged to, where it is necessary to establish, exercise or defend a legal claim, or where it is needed to protect someone's life or safety. If Ideas Central is ever sold or merged, your information may transfer to the buyer, who would remain bound by this policy until you are given notice of any change.
6. Sending information outside South Africa
Ideas Central is established in South Africa, but our infrastructure providers are not. Supabase is a US company running on AWS, Paddle is in the UK/EU, and Cloudflare operates a global edge network. Personal information therefore leaves South Africa in the ordinary course of running the service.
POPIA section 72
Section 72 permits a transfer of personal information to a recipient in a foreign country only if one of its conditions is met. We rely on:
- Section 72(1)(a) — the recipient is subject to a binding agreement that provides an adequate level of protection, with principles for lawful processing that are substantially similar to POPIA's eight conditions and provisions substantially similar to section 72 governing onward transfers. We give effect to this through data processing agreements with each sub-processor, incorporating the EU Standard Contractual Clauses and equivalent onward-transfer restrictions.
- Section 72(1)(c) — the transfer is necessary for the performance of a contract between you and us. A browser-based service cannot be delivered without hosting, authentication and payment infrastructure.
Flagged for legal review. Whether the Standard Contractual Clauses, drafted for EU law, satisfy the "substantially similar" test in section 72(1)(a) without a POPIA-specific addendum is unsettled in South African practice. Question 9 in docs/legal-review-notes.md puts this to our attorney directly. Choosing the af-south-1 Supabase region would reduce but not eliminate the exposure, because Paddle and Cloudflare would remain offshore.
GDPR and UK GDPR Chapter V
For customers in the EEA and UK, personal information may be transferred to South Africa and to the United States. Neither South Africa nor the United States (outside the EU-US Data Privacy Framework) benefits from a general adequacy decision covering us.
For those transfers we rely on Article 46(2)(c) Standard Contractual Clauses, and for UK transfers on the UK International Data Transfer Addendum to those clauses, supported by a transfer impact assessment. You may request a copy of the relevant clauses, with commercial terms redacted, from privacy@ideas-central.com.
7. Your rights
You have the following rights. They exist in more than one regime at once, so the table shows where each comes from. Some are qualified; we will tell you if an exception applies and why.
| Right | What it means | POPIA | GDPR / UK GDPR | CCPA/CPRA |
|---|---|---|---|---|
| Access | Confirmation of whether we hold information about you, and a copy of it | s 23, s 24 | Art 15 | Right to know |
| Correction | Fix information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained | s 24 | Art 16 | Right to correct |
| Deletion | Ask us to erase information, subject to records we must keep by law | s 24(1)(b) | Art 17 | Right to delete |
| Objection | Object to processing based on legitimate interests, and to direct marketing at any time | s 11(3) | Art 21 | Opt out of sale/share (we do neither) |
| Restriction | Ask us to pause processing while a dispute about accuracy or lawfulness is resolved | s 14(6) (limited) | Art 18 | — |
| Portability | Receive your data in a structured, commonly used, machine-readable format | Not expressly granted | Art 20 | — |
| Withdraw consent | Withdraw any consent you gave, without affecting earlier processing | s 11(2)(b) | Art 7(3) | — |
| Complain | Take the matter to a regulator | s 74 | Art 77 | Complaint to the California Attorney General or CPPA |
| Non-discrimination | Not be penalised for exercising a privacy right | — | — | Right to non-discrimination |
Portability is granted under the GDPR rather than POPIA, but we extend it to every user regardless of location. You can export your saved part specifications and your files from within the application at any time.
How to exercise a right
Email privacy@ideas-central.com with the right you want to exercise and enough detail for us to find your records. Most requests need nothing more than an email from the address on your account.
- POPIA Form 2. For a formal request for access to personal information under POPIA, the Regulator prescribes Form 2 (Request for Access to Personal Information, made under the POPIA Regulations). We will accept an ordinary email, but we will also accept and process a completed Form 2, and we will send you the form on request.
- Identity verification. We will verify that you are who you say you are before acting, in proportion to the sensitivity of the request. Usually a reply from your registered email address is enough. For deletion of an account, or where the request would expose files, we may require a second factor or a signed confirmation. We will not ask for more information than we need, and any identity documents we receive for this purpose are deleted once verification is complete.
- Agents. An authorised agent may act for you if you give them written permission and we can verify both of you.
- Cost. Free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse and tell you why. POPIA and the PAIA fee regulations permit a prescribed fee for access requests; we will tell you before charging anything.
How quickly we respond
| Regime | Deadline |
|---|---|
| POPIA / PAIA | 30 days, extendable once by a further 30 days where the request is complex or voluminous, with notice to you |
| GDPR and UK GDPR | One month, extendable by two further months for complex or numerous requests, with notice to you within the first month |
| CCPA/CPRA | 45 days, extendable once by a further 45 days with notice |
Our working commitment is 30 days for every request, wherever you are, with an extension only where the law allows it and we have told you.
If you are not satisfied
Tell us first at privacy@ideas-central.com. If we cannot resolve it, you can complain to a regulator.
Information Regulator (South Africa) — our lead regulator JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 PO Box 31533, Braamfontein, Johannesburg, 2017 General enquiries: enquiries@inforegulator.org.za Complaints: POPIAComplaints@inforegulator.org.za https://inforegulator.org.za
European Economic Area — the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. The list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en
United Kingdom — Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, https://ico.org.uk
California — the California Privacy Protection Agency or the Office of the Attorney General.
8. How we protect your information
- Encryption in transit. All traffic to the site and to our APIs uses TLS. HTTP is redirected to HTTPS at the edge.
- Encryption at rest. Database and file storage are encrypted at rest by the underlying platform.
- Row-level security. Our database enforces row-level security policies so that a signed-in user's queries can only reach rows belonging to that user. Authorisation is enforced in the database itself, not only in application code, so a bug in the front end cannot expose another user's parts.
- Private storage buckets. Uploaded and exported files sit in a private bucket. There is no public URL. Access is granted through short-lived signed URLs issued only to the owner.
- Password handling. Passwords are hashed by Supabase Auth using a modern, salted, computationally expensive algorithm. We never store, log or have access to a plain-text password. If you sign in with an OAuth provider, we hold only the provider's identifier.
- Least privilege. Administrative access is limited to those who need it, service keys are scoped to the narrowest role that works, and secrets are held in the platform's secret store rather than in source code.
- Separation of payment data. Card data never enters our systems, so a compromise of Ideas Central cannot expose a card number.
Honest limits
No system is perfectly secure, and we will not claim otherwise. We depend on Supabase, Cloudflare and Paddle, and a serious failure at any of them is a failure we would have to manage rather than prevent. Email is not a secure channel; do not send sensitive information to us by email. Anyone with access to your device or your inbox can reach your account, so keep your password unique and enable a second factor where it is offered.
If there is a breach
| Regime | Obligation |
|---|---|
| POPIA s 22 | Notify the Information Regulator and every affected data subject as soon as reasonably possible after discovering the compromise. Notification to data subjects may be delayed only where a public body responsible for detecting crime says a delay is needed for an investigation. Notice must describe the possible consequences, the measures we intend to take, what you can do to reduce harm, and the identity of the unauthorised person if known |
| GDPR / UK GDPR Art 33 | Notify the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to rights and freedoms |
| GDPR / UK GDPR Art 34 | Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms |
| California | Notify affected residents in the most expedient time possible and without unreasonable delay, under Cal. Civ. Code §1798.82 |
We keep an internal record of every breach and our response, whether or not it was notifiable.
9. Children
Ideas Central is not directed at children. You must be at least 18 to open an account, or the age of majority where you live if that is higher. We do not knowingly collect personal information from anyone under 18.
POPIA treats anyone under 18 as a child and prohibits processing their personal information without the consent of a competent person. The GDPR sets a lower threshold for information society services (between 13 and 16 depending on the member state), but our own rule is the stricter one.
If you believe a child has given us personal information, email privacy@ideas-central.com and we will delete the account and its contents.
10. Keeping and deleting your information
We keep personal information only as long as the table in section 3 says, and then delete or de-identify it.
When you delete your account:
- Your account is deactivated immediately and you can no longer sign in.
- Saved part specifications, uploaded files and exported files are deleted.
- Your profile record and authentication record are retained for 30 days, then deleted. This window exists so that an accidental or disputed deletion can be reversed, and so that we can resolve a billing dispute raised just before deletion. You can ask us in writing to delete immediately instead, and we will do so unless the record is one we must keep.
- Usage events are retained for the balance of their 24-month period, in a form tied to the deleted account identifier, for quota integrity and billing dispute resolution.
- Subscription records are retained for 7 years as a tax and accounting record. We cannot delete these on request; retention is a legal obligation under GDPR Article 17(3)(b) and POPIA section 14(1)(a).
- Paddle keeps its own transaction records under its own retention policy. Ask Paddle to delete an invoice record and it will apply its own legal retention rules.
Backups are cycled on a rolling schedule and a deleted record may persist in an encrypted backup until that backup expires. Backups are not used for any purpose other than restoring the service.
11. Additional notice for California residents
This section supplements the rest of the policy for consumers resident in California, under the CCPA as amended by the CPRA. Terms have the meaning given in that Act.
Categories of personal information collected in the last 12 months:
| CCPA category | What we actually collect | Source | Business purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | Name, email address, account identifier, hashed IP address | You, and your device | Account creation, authentication, quota | Supabase, Resend, Cloudflare |
| Commercial information | Subscription plan, status, billing period, export history | You, and Paddle | Providing the service you paid for, billing, tax records | Supabase, Paddle |
| Internet or network activity | Usage events, server and edge log metadata | Your device | Quota enforcement, security, fault diagnosis | Supabase, Cloudflare |
| Geolocation data | Country only, at the coarse level you give us or that the edge infers | You, and your device | Tax determination by Paddle, service configuration | Paddle, Cloudflare |
| Other | Saved part specifications, uploaded and exported files | You | Delivering the service | Supabase |
We do not collect sensitive personal information as defined by the CPRA, and we therefore have nothing to limit under the right to limit use of sensitive personal information.
No sale and no sharing. We have not sold personal information and have not shared it for cross-context behavioural advertising in the preceding 12 months, and we do not do so now. We do not sell or share the personal information of consumers under 16.
Your rights. You have the right to know what we collect and why, the right to delete, the right to correct, the right to opt out of sale or sharing (there is nothing to opt out of), and the right not to be discriminated against for exercising any of them. We do not offer financial incentives for personal information, and exercising a privacy right will not change your price, your plan or the service you receive.
To exercise any of these, email privacy@ideas-central.com. Section 7 explains verification and timing.
12. Changes to this policy
We will update this policy when the service changes or the law changes. The version and date at the top always reflect the current text.
- For minor changes (clarifications, contact details, typos) we update the page and change the date.
- For material changes (a new category of data, a new purpose, a new sub-processor handling your content, any change that reduces your protections) we will give notice by email to your registered address and by an in-product notice, at least 30 days before the change takes effect.
- Where a change requires your consent, we will ask for it separately. Continuing to use the service will not be treated as consent to something that legally requires consent.
Previous versions are available on request from legal@ideas-central.com.
13. Contact
| Purpose | Address |
|---|---|
| Privacy, data subject requests, Information Officer | privacy@ideas-central.com |
| Legal notices | legal@ideas-central.com |
| Everything else | info@ideas-central.com |
Postal: [COMPANY LEGAL NAME] (Pty) Ltd, [STREET ADDRESS], South Africa
Related documents
- Cookie Policy
- Terms of Service —
[STATUS: confirm location] docs/product-facts.md— internal source of truth for the facts in this policydocs/legal-review-notes.md— briefing note for the reviewing attorney